package webgoat.dao.impl;

import org.springframework.stereotype.Component;
import webgoat.dao.SqlDao;
import webgoat.pojo.User;
import webgoat.utils.JdbcUtil;
import webgoat.utils.SqlConnection;

import java.sql.Connection;
import java.sql.ResultSet;
import java.sql.SQLException;
import java.sql.Statement;
import java.util.ArrayList;
import java.util.List;

/**
 * @auth Administrator
 * @date 2019-11-18 10:56
 */

@Component
public class SqlDaoImpl implements SqlDao {

    @Override
    public List<User> queryUser(User user) throws SQLException {
        // 获取连接
        Connection conn = SqlConnection.getConnection();
        // 构建查询语句
        String query = "select * from users where username='" + user.getUsername() + "'";
        System.out.println(query);
        // 创建statement对象
        Statement statement = conn.createStatement();
        // 执行查询获取结果集ResultSet对象
        ResultSet resultSet = statement.executeQuery(query);
        // 遍历ResultSet对象获取结果
        List<User> userList = new ArrayList<>();

        while (resultSet.next()) {
            User goal = new User();
            goal.setId(resultSet.getInt("id"));
            goal.setUsername(resultSet.getString("username"));
            goal.setPassword(resultSet.getNString("password"));
            System.out.println(goal);
            userList.add(goal);
        }
        return userList;
    }
}
